logoalt Hacker News

Authorization terminology is a mess: Let's fix it

45 pointsby andychiarelast Tuesday at 2:18 PM20 commentsview on HN

Comments

usernametaken29today at 9:11 AM

https://xkcd.com/927

Nice work and all regardless

show 2 replies
tuberreacttoday at 8:29 AM

turns out naming is important

show 2 replies
jiggawattstoday at 9:35 AM

I love how the OIDC standard is littered with “authentication identity token code id cookie identifier” and many subtle variations of homonyms in slightly different combinations and orders.

I’m sure someone thought it all made perfect sense.

Probably someone who never confuses “empathy” and “sympathy” while also carefully distinguishing between “should” and “ought”.

show 1 reply
andrewshaduratoday at 9:22 AM

Unclosable cookie banner. Top notch website engineering.

black_knighttoday at 8:54 AM

> can this subject perform this action on this object?

IMHO, the most elegant method to answer this question is capability based access control. If the subject can utter the action, then it can perform it. And then delegation is the transfer of nouns and verbs to perform the utterances.

show 3 replies
bijowo1676today at 8:38 AM

excellent article, very thorough and nuanced explanation.

Quarrelsometoday at 9:10 AM

Nice!

I'd like to fix the prior abstract. Auth and auth upsets me greatly cos we have:

Authentication & Authorization

and we call both/either auth. Hence please help me make this a thing:

AuthENTIcation & AuthORIzation : ENTI & ORI

ENTI- can you enter, ORI (or ORIZ) what can you do?

show 3 replies